Nicolas Verdier. (n.d.). Retrieved January 29, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
ToolPupy | Pupy can execute Lazagne as well as Mimikatz using PowerShell. |
| T1003.004 LSA Secrets |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1003.005 Cached Domain Credentials |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1016 System Network Configuration Discovery |
ToolPupy | Pupy has built in commands to identify a host’s IP address and find out other network configuration settings by viewing connected sessions. |
| T1021.001 Remote Desktop Protocol |
ToolPupy | Pupy can enable/disable RDP connection and can start a remote desktop session using a browser web socket client. |
| T1033 System Owner/User Discovery |
ToolPupy | Pupy can enumerate local information for Linux hosts and find currently logged on users for Windows hosts. |
| T1041 Exfiltration Over C2 Channel |
ToolPupy | Pupy can send screenshots files, keylogger data, files, and recorded audio back to the C2 server. |
| T1046 Network Service Discovery |
ToolPupy | Pupy has a built-in module for port scanning. |
| T1049 System Network Connections Discovery |
ToolPupy | Pupy has a built-in utility command for |
| T1055.001 Dynamic-link Library Injection |
ToolPupy | Pupy can migrate into another process using reflective DLL injection. |
| T1056.001 Keylogging |
ToolPupy | Pupy uses a keylogger to capture keystrokes it then sends back to the server after it is stopped. |
| T1057 Process Discovery |
ToolPupy | Pupy can list the running processes and get the process ID and parent process’s ID. |
| T1059.001 PowerShell |
ToolPupy | Pupy has a module for loading and executing PowerShell scripts. |
| T1059.006 Python |
ToolPupy | Pupy can use an add on feature when creating payloads that allows you to create custom Python scripts (“scriptlets”) to perform tasks offline (without requiring a session) such as sandbox detection, adding persistence, etc. |
| T1071.001 Web Protocols |
ToolPupy | Pupy can communicate over HTTP for C2. |
| T1082 System Information Discovery |
ToolPupy | Pupy can grab a system’s information including the OS version, architecture, etc. |
| T1083 File and Directory Discovery |
ToolPupy | Pupy can walk through directories and recursively search for strings in files. |
| T1087.001 Local Account |
ToolPupy | Pupy uses PowerView and Pywerview to perform discovery commands such as net user, net group, net local group, etc. |
| T1105 Ingress Tool Transfer |
ToolPupy | Pupy can upload and download to/from a victim machine. |
| T1113 Screen Capture |
ToolPupy | Pupy can drop a mouse-logger that will take small screenshots around at each click and then send back to the server. |
| T1114.001 Local Email Collection |
ToolPupy | Pupy can interact with a victim’s Outlook session and look through folders and emails. |
| T1123 Audio Capture |
ToolPupy | Pupy can record sound with the microphone. |
| T1125 Video Capture |
ToolPupy | Pupy can access a connected webcam and capture pictures. |
| T1134.001 Token Impersonation/Theft |
ToolPupy | Pupy can obtain a list of SIDs and provide the option for selecting process tokens to impersonate. |
| T1135 Network Share Discovery |
ToolPupy | Pupy can list local and remote shared drives and folders over SMB. |
| T1136.001 Local Account |
ToolPupy | Pupy can user PowerView to execute “net user” commands and create local system accounts. |
| T1136.002 Domain Account |
ToolPupy | Pupy can user PowerView to execute “net user” commands and create domain accounts. |
| T1497.001 System Checks |
ToolPupy | Pupy has a module that checks a number of indicators on the system to determine if its running on a virtual machine. |
| T1543.002 Systemd Service |
ToolPupy | Pupy can be used to establish persistence using a systemd service. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolPupy | Pupy adds itself to the startup folder or adds itself to the Registry key |
| T1548.002 Bypass User Account Control |
ToolPupy | Pupy can bypass Windows UAC through either DLL hijacking, eventvwr, or appPaths. |
| T1550.003 Pass the Ticket |
ToolPupy | Pupy can also perform pass-the-ticket. |
| T1552.001 Credentials In Files |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1555 Credentials from Password Stores |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1555.003 Credentials from Web Browsers |
ToolPupy | Pupy can use Lazagne for harvesting credentials. |
| T1557.001 Name Resolution Poisoning and SMB Relay |
ToolPupy | Pupy can sniff plaintext network credentials and use NBNS Spoofing to poison name services. |
| T1560.001 Archive via Utility |
ToolPupy | Pupy can compress data with Zip before sending it over C2. |
| T1569.002 Service Execution |
ToolPupy | Pupy uses PsExec to execute a payload or commands on a remote host. |
| T1573.002 Asymmetric Cryptography |
ToolPupy | Pupy's default encryption for its C2 communication channel is SSL, but it also has transport options for RSA and AES. |
| T1685.005 Clear Windows Event Logs |
ToolPupy | Pupy has a module to clear event logs with PowerShell. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.